Security at Otaly
How we protect your events, your attendees, and their data.
Last updated: 2026
Our approach
Security is built into how we operate Otaly. We protect host and attendee data with layered safeguards and review our practices as the platform grows.
Data protection
Traffic to Otaly is encrypted in transit with TLS. Sensitive data is protected at rest, and access to production systems is restricted to authorized personnel on a need-to-know basis.
Payments
Card payments are handled by PCI-DSS-compliant third-party payment providers. Otaly does not store full card numbers; we receive only the limited transaction data needed to run ticketing and payouts.
Infrastructure & access
Otaly runs on reputable cloud infrastructure with isolation between environments. We apply least-privilege access controls, authentication safeguards, and monitoring to detect and respond to abuse.
Responsible disclosure
If you believe you have found a security vulnerability, we want to hear from you. Please report it privately through our contact channel and give us a reasonable opportunity to investigate and remediate before any public disclosure. We do not pursue good-faith researchers who follow responsible disclosure.
Machine-readable contact details are published at /.well-known/security.txt.
Report a vulnerability
Reach our security team through the contact page.